Back to skill

Security audit

BurnThisShit

Security checks across malware telemetry and agentic risk

Overview

This skill openly performs destructive session cleanup, but it tells the agent to erase records immediately without warning or confirmation, so it needs careful review before installation.

Install only if you intentionally want an agent-accessible tool that can permanently erase OpenClaw session records. Use explicit commands and specific session IDs, avoid --force unless you have already reviewed what will be deleted, and do not rely on this skill where auditability or recovery matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The skill’s safety section says explicit confirmation is required unless --force is passed, but the main invocation instructions tell the agent to run the destructive wipe immediately and use --force. This bypasses the only meaningful safeguard for an irreversible deletion operation and creates a high risk of accidental or unauthorized destruction of forensic and audit artifacts.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger condition allows invocation via vague natural language without defining strict intent boundaries or examples. In a destructive skill, this can cause the agent to infer consent from ambiguous user phrasing and launch irreversible deletion when the user may only be asking for information or a dry run.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill is framed as an immediate forensic obliteration tool and instructs execution without an upfront warning about irreversible data loss. Because it targets transcripts, trajectories, backups, deleted archives, and sessions metadata, the context makes this especially dangerous by removing both operational history and evidence of prior activity.

Ssd 4

High
Confidence
98% confidence
Finding
The instruction to 'grab the current session ID and run the burn script immediately' and 'Do not explain' normalizes covert, no-confirmation destruction of audit evidence. In context, this is not just ordinary cleanup: it is designed to erase session records and traces in a way that impedes review, accountability, and forensic investigation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.